<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Application Logs Monitoring in Splunk in Other Usage</title>
    <link>https://community.splunk.com/t5/Other-Usage/Application-Logs-Monitoring-in-Splunk/m-p/669964#M1624</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;We have configured application log monitoring on windows application servers. The log path has a folder where all the _json files are stored. There are more that 300+ json files in each folder with different time stamps and dates. We have configured inputs.conf as shown below with ignoreOlderThan =2d so that Splunk should not consume more CPU/memory. But still we could see memory and CPU of the application server is going high. Kindly suggest best practice methods so that Splunk universal forwarder wont consume more CPU and memory.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;[monitor://C:\Logs\xyz\zbc\*]&lt;BR /&gt;disabled = false&lt;BR /&gt;index = preprod_logs&lt;BR /&gt;interval =300&lt;BR /&gt;ignoreOlderThan = 2d&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 28 Nov 2023 06:02:59 GMT</pubDate>
    <dc:creator>Manjunath_Splnk</dc:creator>
    <dc:date>2023-11-28T06:02:59Z</dc:date>
    <item>
      <title>Application Logs Monitoring in Splunk</title>
      <link>https://community.splunk.com/t5/Other-Usage/Application-Logs-Monitoring-in-Splunk/m-p/669964#M1624</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;We have configured application log monitoring on windows application servers. The log path has a folder where all the _json files are stored. There are more that 300+ json files in each folder with different time stamps and dates. We have configured inputs.conf as shown below with ignoreOlderThan =2d so that Splunk should not consume more CPU/memory. But still we could see memory and CPU of the application server is going high. Kindly suggest best practice methods so that Splunk universal forwarder wont consume more CPU and memory.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;[monitor://C:\Logs\xyz\zbc\*]&lt;BR /&gt;disabled = false&lt;BR /&gt;index = preprod_logs&lt;BR /&gt;interval =300&lt;BR /&gt;ignoreOlderThan = 2d&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2023 06:02:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Usage/Application-Logs-Monitoring-in-Splunk/m-p/669964#M1624</guid>
      <dc:creator>Manjunath_Splnk</dc:creator>
      <dc:date>2023-11-28T06:02:59Z</dc:date>
    </item>
  </channel>
</rss>

